82_FR_61505 82 FR 61258 - National Cybersecurity Center of Excellence (NCCoE) Transport Layer Security (TLS) Server Certificate Management Building Block

82 FR 61258 - National Cybersecurity Center of Excellence (NCCoE) Transport Layer Security (TLS) Server Certificate Management Building Block

DEPARTMENT OF COMMERCE
National Institute of Standards and Technology

Federal Register Volume 82, Issue 247 (December 27, 2017)

Page Range61258-61260
FR Document2017-27893

The National Institute of Standards and Technology (NIST) invites organizations to provide products and technical expertise to support and demonstrate security platforms for the Transport Layer Security (TLS) Server Certificate Management Building Block. This notice is the initial step for the National Cybersecurity Center of Excellence (NCCoE) in collaborating with technology companies to address cybersecurity challenges identified under the TLS Server Certificate Management Building Block. Participation in the building block is open to all interested organizations.

Federal Register, Volume 82 Issue 247 (Wednesday, December 27, 2017)
[Federal Register Volume 82, Number 247 (Wednesday, December 27, 2017)]
[Notices]
[Pages 61258-61260]
From the Federal Register Online  [www.thefederalregister.org]
[FR Doc No: 2017-27893]


-----------------------------------------------------------------------

DEPARTMENT OF COMMERCE

National Institute of Standards and Technology

[Docket No.: 171108999-7999-01]


National Cybersecurity Center of Excellence (NCCoE) Transport 
Layer Security (TLS) Server Certificate Management Building Block

AGENCY: National Institute of Standards and Technology, Department of 
Commerce.

ACTION: Notice.

-----------------------------------------------------------------------

SUMMARY: The National Institute of Standards and Technology (NIST) 
invites organizations to provide products and technical expertise to 
support and demonstrate security platforms for the Transport Layer

[[Page 61259]]

Security (TLS) Server Certificate Management Building Block. This 
notice is the initial step for the National Cybersecurity Center of 
Excellence (NCCoE) in collaborating with technology companies to 
address cybersecurity challenges identified under the TLS Server 
Certificate Management Building Block. Participation in the building 
block is open to all interested organizations.

DATES: Interested parties must contact NIST to request a letter of 
interest template to be completed and submitted to NIST. Letters of 
interest will be accepted on a first come, first served basis. 
Collaborative activities will commence as soon as enough completed and 
signed letters of interest have been returned to address all the 
necessary components and capabilities, but no earlier than January 26, 
2018. When the building block has been completed, NIST will post a 
notice on the NCCoE TLS Server Certificate Management Building Block 
website at: https://nccoe.nist.gov/projects/building-blocks/tls-server-certificate-management announcing the completion of the building block 
and informing the public that it will no longer accept letters of 
interest for this building block.

ADDRESSES: The NCCoE is located at 9700 Great Seneca Highway, 
Rockville, MD 20850. Letters of interest must be submitted to [email protected] or via hardcopy to National Institute of Standards 
and Technology, NCCoE; 9700 Great Seneca Highway, Rockville, MD 20850. 
Organizations whose letters of interest are accepted in accordance with 
the process set forth in the SUPPLEMENTARY INFORMATION section of this 
notice will be asked to sign a consortium Cooperative Research and 
Development Agreement (CRADA) with NIST. An NCCoE consortium CRADA 
template can be found at: http://nccoe.nist.gov/node/138.

FOR FURTHER INFORMATION CONTACT: Tim Polk, William Haag, Jr. and 
Murugiah Souppaya via email to [email protected]; by 
telephone 301-975-0239; or by mail to National Institute of Standards 
and Technology, NCCoE; 9700 Great Seneca Highway, Rockville, MD 20850. 
Additional details about the TLS Server Certificate Management Building 
Block are available at: https://nccoe.nist.gov/projects/building-blocks/tls-server-certificate-management.

SUPPLEMENTARY INFORMATION:
    Background: The NCCoE, part of NIST, is a public-private 
collaboration for accelerating the widespread adoption of integrated 
cybersecurity tools and technologies. The NCCoE brings together experts 
from industry, government, and academia under one roof to develop 
practical, interoperable cybersecurity approaches that address the 
real-world needs of complex Information Technology (IT) systems. By 
accelerating dissemination and use of these integrated tools and 
technologies for protecting IT assets, the NCCoE will enhance trust in 
U.S. IT communications, data, and storage systems; reduce risk for 
companies and individuals using IT systems; and encourage development 
of innovative, job-creating cybersecurity products and services.
    Process: NIST is soliciting responses from all sources of relevant 
security capabilities (see below) to enter into a Cooperative Research 
and Development Agreement (CRADA) to provide products and technical 
expertise to support and demonstrate security platforms for the TLS 
Server Certificate Management Building Block. The full building block 
can be viewed at: https://nccoe.nist.gov/projects/building-blocks/tls-server-certificate-management.
    Interested parties should contact NIST using the information 
provided in the FOR FURTHER INFORMATION CONTACT section of this notice. 
NIST will then provide each interested party with a letter of interest 
template, which the party must complete, certify that it is accurate, 
and submit to NIST. NIST will contact interested parties if there are 
questions regarding the responsiveness of the letters of interest to 
the building block objective or requirements identified below. NIST 
will select participants who have submitted complete letters of 
interest on a first come, first served basis within each category of 
product components or capabilities listed below up to the number of 
participants in each category necessary to carry out this building 
block. However, there may be continuing opportunity to participate even 
after initial activity commences. Selected participants will be 
required to enter into a consortium CRADA with NIST (for reference, see 
ADDRESSES section above). NIST published a notice in the Federal 
Register on October 19, 2012 (77 FR 64314) inviting U.S. companies to 
enter into a National Cybersecurity Excellence Partnerships (NCEPs) in 
furtherance of the NCCoE. For this demonstration project, NCEP partners 
will not be given priority for participation.
    Building Block Objective: The building block objective is to 
improve the overall security of TLS certificates and private keys. A 
detailed description of the TLS Server Certificate Management Building 
Block is available at: https://nccoe.nist.gov/projects/building-blocks/tls-server-certificate-management.
    Requirements: Each responding organization's letter of interest 
should identify which security platform component(s) or capability(ies) 
it is offering. Letters of interest should not include company 
proprietary information, and all components and capabilities must be 
commercially available. Components are listed in section 3 of the TLS 
Server Certificate Management Building Block (for reference, please see 
the link in the Process section above) and include, but are not limited 
to:
     TLS servers in the Cloud.
     Public Certification Authority (CA).
     TLS Servers including webservers, application servers, or 
other services.
     TLS Load Balancers.
     DevOps Frameworks including application containers.
     Internal CAs.
     Certificate Management systems.
     Certificate Network Scanning Tools including vulnerability 
scanning.
    Each responding organization's letter of interest should identify 
how their products address one or more of the following desired 
solution characteristics in Section 3 of the TLS Server Certificate 
Management Building Block (for reference, please see the link in the 
Process section above):
    1. External Systems--The architecture will include the following 
components that typically reside outside the organizational firewall:
     TLS Servers in the Cloud Environment: The cloud 
environment will include multiple cloud instances acting as TLS 
servers. Certificates will be deployed and managed on these systems.
     Public CA: A publicly trusted CA will be used to issue one 
or more of the certificates used on TLS servers on the internal or 
external systems.
    2. Internal Systems--The architecture will include several systems 
that are typically deployed within organizational network environments.
     TLS Servers: Multiple systems will be configured as TLS 
servers (e.g., webserver, application server, or other service). 
Certificates will be deployed and managed on these systems.
     Load Balancer: A load balancer will act as a TLS server 
with a certificate and will facilitate the load balancing of traffic to 
the other TLS servers.
     DevOps Framework(s): One or more DevOps frameworks (e.g., 
Docker) will be used to automate the management of cloud instances and 
the deployment of certificates on those instances.
     Internal CA: An internal CA will be used to issue 
certificates to some of the TLS servers.

[[Page 61260]]

     Certificate Manager: A certificate management system will 
be used to inventory and manage TLS server certificates deployed in the 
environment.
     Certificate Network Scanning Tool: A tool, such as a 
vulnerability scanning or other tool, will be used to facilitate the 
discovery of TLS server certificates via network scanning.
    3. Stakeholders/Roles--Humans play an important part in the 
management of TLS server certificates in enterprises; therefore, the 
following roles will be represented:
     Line of Business/Application Owner: People in leadership 
positions who are responsible for the line of business or application 
and who will drive the need for certificates to be deployed.
     System Administrators: Responsible for managing TLS 
servers and ensuring that the load balancer will be represented.
     DevOps Developer: Responsible for programming/configuring 
and managing the DevOps framework.
     Approver: One or more stakeholders who will review and 
approve/reject certificate management operations.
     PKI Team: One or more individuals who will manage the 
certificate management system and public/internal CAs.
    Responding organizations need to understand and, in their letters 
of interest, commit to provide:
    1. Access for all participants' project teams to component 
interfaces and the organization's experts necessary to make functional 
connections among security platform components.
    2. Support for development and demonstration of the TLS Server 
Certificate Management Building Block in NCCoE facilities which will be 
conducted in a manner consistent with the following standards and 
guidance: OMB Circular A-130; FIPS 200; FIPS 140-2; NIST Special 
Publications 800-52, 800-57, 800-63-3, 800-77, 800-177; NIST Framework 
for Improving Critical Infrastructure Cybersecurity; and internet 
Engineering Task Force (IETF) Requests for Comments (RFCs) 2246, 4346, 
5280 and 5246. The project will also be informed by two in-progress 
IETF standards draft-ietf-tls-tls13-21 The Transport Layer Security 
(TLS) Protocol Version 1.3 and draft-ietf-acme-acme-07 Automatic 
Certificate Management Environment (ACME).
    Additional details about the TLS Server Certificate Management 
Building Block are available at: https://nccoe.nist.gov/projects/building-blocks/tls-server-certificate-management.
    NIST cannot guarantee that all the products proposed by respondents 
will be used in the demonstration. Each prospective participant will be 
expected to work collaboratively with NIST staff and other project 
participants under the terms of the consortium CRADA in the development 
of the TLS Server Certificate Management Building Block. Prospective 
participants' contribution to the collaborative effort will include 
assistance in establishing the necessary interface functionality, 
connection and set-up capabilities and procedures, demonstration 
harnesses, environmental and safety conditions for use, integrated 
platform user instructions, and demonstration plans and scripts 
necessary to demonstrate the desired capabilities. Each participant 
will train NIST personnel, as necessary, to operate its product in 
capability demonstrations. Following successful demonstrations, NIST 
will publish a description of the security platform and its performance 
characteristics sufficient to permit other organizations to develop and 
deploy security platforms that meet the security objectives of the TLS 
Server Certificate Management Building Block. These descriptions will 
be public information. Under the terms of the consortium CRADA, NIST 
will support development of interfaces among participants' products by 
providing IT infrastructure, laboratory facilities, office facilities, 
collaboration facilities, and staff support to component composition, 
security platform documentation, and demonstration activities.
    The dates of the demonstration of the TLS Server Certificate 
Management Building Block capability will be announced on the NCCoE 
website at least two weeks in advance at http://nccoe.nist.gov/. The 
expected outcome of the demonstration is to improve security of TLS 
certificates and private keys within the enterprise. Participating 
organizations will gain from the knowledge that their products are 
interoperable with other participants' offerings.
    For additional information on the NCCoE governance, business 
processes, and NCCoE operational structure, visit the NCCoE website 
http://nccoe.nist.gov/.

Kevin Kimball,
NIST Chief of Staff.
[FR Doc. 2017-27893 Filed 12-26-17; 8:45 am]
BILLING CODE 3510-13-P



                                               61258                    Federal Register / Vol. 82, No. 247 / Wednesday, December 27, 2017 / Notices

                                               and technology, which is why attackers                    6. Provides system command control.                 its product in capability demonstrations
                                               or malicious insiders seek to gain access                 7. Counters password obfuscation                    to the Financial Services community.
                                               to them. Hence, it is critical to monitor,              (hidden passwords).                                   Following successful demonstrations,
                                               audit, control, and manage privileged                     8. Supports password management                     NIST will publish a description of the
                                               account usage. Many organizations,                      (vaults, changes, storage).                           security platform and its performance
                                               including financial sector companies,                     9. Supports activity logging (textual               characteristics sufficient to permit other
                                               face challenges managing privileged                     and video).                                           organizations to develop and deploy
                                               accounts. To address these challenges,                    10. Supports real time activity                     security platforms that meet the security
                                               the National Cybersecurity Center of                    monitoring.                                           objectives of the Privileged Account
                                               Excellence (NCCoE) plans to                               11. Includes support functions needed               Management for the Financial Services
                                               demonstrate a PAM capability that                       by the typical user.                                  sector use case. These descriptions will
                                               effectively protects, monitors, and                       12. Supports privilege escalation                   be public information.
                                               manages privileged account access. The                  management.                                              Under the terms of the consortium
                                               project addresses privileged account life                 13. Supports forensic investigation                 CRADA, NIST will support
                                               cycle management, authentication,                       data management.                                      development of interfaces among
                                               authorization, auditing, and access                       14. Provides support for workflow                   participants’ products by providing IT
                                               controls.                                               management.                                           infrastructure, laboratory facilities,
                                                  A detailed description of the                          15. Enables emergency (break glass)                 office facilities, collaboration facilities,
                                               Privileged Account Management is                        scenario support.                                     and staff support to component
                                               available at: https://nccoe.nist.gov/                     16. Includes policy management
                                                                                                                                                             composition, security platform
                                               projects/use-cases/privileged-account-                  support.
                                                                                                                                                             documentation, and demonstration
                                                                                                         17. Supports single sign-on.
                                               management.                                                                                                   activities.
                                                  Requirements: Each responding                          18. Permits system and privileged
                                                                                                       account discovery.                                       The dates of the demonstration of the
                                               organization’s letter of interest should                                                                      Privileged Account Management for the
                                                                                                         Responding organizations need to
                                               identify which security platform                                                                              Financial Services sector capability will
                                                                                                       understand and, in their letters of
                                               component(s) or capability(ies) it is                                                                         be announced on the NCCoE website at
                                                                                                       interest, commit to provide:
                                               offering. Letters of interest should not                                                                      least two weeks in advance at http://
                                                                                                         1. Access for all participants’ project
                                               include company proprietary                                                                                   nccoe.nist.gov/. The expected outcome
                                                                                                       teams to component interfaces and the
                                               information, and all components and                                                                           of the demonstration is to improve
                                                                                                       organization’s experts necessary to make
                                               capabilities must be commercially                                                                             privileged account management across
                                                                                                       functional connections among security
                                               available. Components are listed in                                                                           an entire Financial Services sector
                                                                                                       platform components
                                               section 3 of the Privileged Account                       2. Support for development and                      enterprise. Participating organizations
                                               Management for the Financial Services                   demonstration of the Privileged Account               will gain from the knowledge that their
                                               sector use case (for reference, please see              Management for the Financial Services                 products are interoperable with other
                                               the link in the PROCESS section above)                  sector use case in NCCoE facilities                   participants’ offerings.
                                               and include, but are not limited to:                    which will be conducted in a manner                      For additional information on the
                                               • Privileged account control                            consistent with the following standards               NCCoE governance, business processes,
                                               • Privileged account command filtering                  and guidance: FIPS 140–2, FIPS 199,                   and NCCoE operational structure, visit
                                                  (allow or deny specific comments,                    FIPS 200, FIPS 201, SP 800–53, and SP                 the NCCoE website http://
                                                  such as disk formatting)                             800–63.                                               nccoe.nist.gov/.
                                               • Multifactor authentication capability                   Additional details about the
                                               • Access logging/database system                                                                              Kevin Kimball,
                                               • Password management                                   Privileged Account Management for the                 NIST Chief of Staff.
                                               • Separation of duties management                       Financial Services sector use case are
                                                                                                                                                             [FR Doc. 2017–27869 Filed 12–26–17; 8:45 am]
                                               • Support least privileged policies                     available at: https://nccoe.nist.gov/
                                                                                                                                                             BILLING CODE 3510–13–P
                                               • Password obfuscation (hiding                          projects/use-cases/privileged-account-
                                                  passwords from PAM users)                            management.
                                               • Temporary accounts                                      NIST cannot guarantee that all of the               DEPARTMENT OF COMMERCE
                                               • Log management (analytics, storage,                   products proposed by respondents will
                                                  alerting)                                            be used in the demonstration. Each                    National Institute of Standards and
                                                  Each responding organization’s letter                prospective participant will be expected              Technology
                                               of interest should identify how their                   to work collaboratively with NIST staff
                                                                                                       and other project participants under the              [Docket No.: 171108999–7999–01]
                                               products address one or more of the
                                               following desired solution                              terms of the consortium CRADA in the
                                                                                                                                                             National Cybersecurity Center of
                                               characteristics in section 3 of the                     development of the Privileged Account
                                                                                                                                                             Excellence (NCCoE) Transport Layer
                                               Privileged Account Management for the                   Management for the Financial Services
                                                                                                                                                             Security (TLS) Server Certificate
                                               Financial Services sector use case (for                 sector capability. Prospective
                                                                                                                                                             Management Building Block
                                               reference, please see the link in the                   participants’ contribution to the
                                               PROCESS section above):                                 collaborative effort will include                     AGENCY: National Institute of Standards
                                                  1. Is easy to use for both PAM system                assistance in establishing the necessary              and Technology, Department of
                                               administrators and PAM system users.                    interface functionality, connection and               Commerce.
                                                  2. Provides protection for data at rest              set-up capabilities and procedures,                   ACTION: Notice.
daltland on DSKBBV9HB2PROD with NOTICES




                                               and data in transit.                                    demonstration harnesses, environmental
                                                  3. Is complementary to existing access               and safety conditions for use, integrated             SUMMARY:   The National Institute of
                                               management.                                             platform user instructions, and                       Standards and Technology (NIST)
                                                  4. Integrates with directories.                      demonstration plans and scripts                       invites organizations to provide
                                                  5. Provides account use control                      necessary to demonstrate the desired                  products and technical expertise to
                                               (policy enforcement and decision                        capabilities. Each participant will train             support and demonstrate security
                                               making).                                                NIST personnel, as necessary, to operate              platforms for the Transport Layer


                                          VerDate Sep<11>2014   21:43 Dec 26, 2017   Jkt 244001   PO 00000   Frm 00008   Fmt 4703   Sfmt 4703   E:\FR\FM\27DEN1.SGM   27DEN1


                                                                        Federal Register / Vol. 82, No. 247 / Wednesday, December 27, 2017 / Notices                                           61259

                                               Security (TLS) Server Certificate                       government, and academia under one                    building-blocks/tls-server-certificate-
                                               Management Building Block. This                         roof to develop practical, interoperable              management.
                                               notice is the initial step for the National             cybersecurity approaches that address                    Requirements: Each responding
                                               Cybersecurity Center of Excellence                      the real-world needs of complex                       organization’s letter of interest should
                                               (NCCoE) in collaborating with                           Information Technology (IT) systems.                  identify which security platform
                                               technology companies to address                         By accelerating dissemination and use                 component(s) or capability(ies) it is
                                               cybersecurity challenges identified                     of these integrated tools and                         offering. Letters of interest should not
                                               under the TLS Server Certificate                        technologies for protecting IT assets, the            include company proprietary
                                               Management Building Block.                              NCCoE will enhance trust in U.S. IT                   information, and all components and
                                               Participation in the building block is                  communications, data, and storage                     capabilities must be commercially
                                               open to all interested organizations.                   systems; reduce risk for companies and                available. Components are listed in
                                               DATES: Interested parties must contact                  individuals using IT systems; and                     section 3 of the TLS Server Certificate
                                               NIST to request a letter of interest                    encourage development of innovative,                  Management Building Block (for
                                               template to be completed and submitted                  job-creating cybersecurity products and               reference, please see the link in the
                                               to NIST. Letters of interest will be                    services.                                             Process section above) and include, but
                                               accepted on a first come, first served                     Process: NIST is soliciting responses              are not limited to:
                                               basis. Collaborative activities will                    from all sources of relevant security                    • TLS servers in the Cloud.
                                               commence as soon as enough completed                    capabilities (see below) to enter into a                 • Public Certification Authority (CA).
                                               and signed letters of interest have been                Cooperative Research and Development                     • TLS Servers including webservers,
                                               returned to address all the necessary                   Agreement (CRADA) to provide                          application servers, or other services.
                                                                                                       products and technical expertise to                      • TLS Load Balancers.
                                               components and capabilities, but no                                                                              • DevOps Frameworks including
                                               earlier than January 26, 2018. When the                 support and demonstrate security
                                                                                                       platforms for the TLS Server Certificate              application containers.
                                               building block has been completed,                                                                               • Internal CAs.
                                               NIST will post a notice on the NCCoE                    Management Building Block. The full
                                                                                                                                                                • Certificate Management systems.
                                               TLS Server Certificate Management                       building block can be viewed at: https://                • Certificate Network Scanning Tools
                                               Building Block website at: https://                     nccoe.nist.gov/projects/building-blocks/              including vulnerability scanning.
                                               nccoe.nist.gov/projects/building-blocks/                tls-server-certificate-management.                       Each responding organization’s letter
                                               tls-server-certificate-management                          Interested parties should contact NIST             of interest should identify how their
                                               announcing the completion of the                        using the information provided in the                 products address one or more of the
                                               building block and informing the public                 FOR FURTHER INFORMATION CONTACT
                                                                                                                                                             following desired solution
                                               that it will no longer accept letters of                section of this notice. NIST will then                characteristics in Section 3 of the TLS
                                               interest for this building block.                       provide each interested party with a                  Server Certificate Management Building
                                                                                                       letter of interest template, which the                Block (for reference, please see the link
                                               ADDRESSES: The NCCoE is located at
                                                                                                       party must complete, certify that it is               in the Process section above):
                                               9700 Great Seneca Highway, Rockville,
                                                                                                       accurate, and submit to NIST. NIST will                  1. External Systems—The architecture
                                               MD 20850. Letters of interest must be
                                                                                                       contact interested parties if there are               will include the following components
                                               submitted to tls-cert-mgmt-nccoe@
                                                                                                       questions regarding the responsiveness                that typically reside outside the
                                               nist.gov or via hardcopy to National
                                                                                                       of the letters of interest to the building            organizational firewall:
                                               Institute of Standards and Technology,                  block objective or requirements
                                               NCCoE; 9700 Great Seneca Highway,                                                                                • TLS Servers in the Cloud
                                                                                                       identified below. NIST will select                    Environment: The cloud environment
                                               Rockville, MD 20850. Organizations                      participants who have submitted
                                               whose letters of interest are accepted in                                                                     will include multiple cloud instances
                                                                                                       complete letters of interest on a first               acting as TLS servers. Certificates will
                                               accordance with the process set forth in                come, first served basis within each
                                               the SUPPLEMENTARY INFORMATION section                                                                         be deployed and managed on these
                                                                                                       category of product components or                     systems.
                                               of this notice will be asked to sign a
                                               consortium Cooperative Research and
                                                                                                       capabilities listed below up to the                      • Public CA: A publicly trusted CA
                                                                                                       number of participants in each category               will be used to issue one or more of the
                                               Development Agreement (CRADA) with                      necessary to carry out this building
                                               NIST. An NCCoE consortium CRADA                                                                               certificates used on TLS servers on the
                                                                                                       block. However, there may be                          internal or external systems.
                                               template can be found at: http://                       continuing opportunity to participate                    2. Internal Systems—The architecture
                                               nccoe.nist.gov/node/138.                                even after initial activity commences.                will include several systems that are
                                               FOR FURTHER INFORMATION CONTACT: Tim                    Selected participants will be required to             typically deployed within
                                               Polk, William Haag, Jr. and Murugiah                    enter into a consortium CRADA with                    organizational network environments.
                                               Souppaya via email to tls-cert-mgmt-                    NIST (for reference, see ADDRESSES                       • TLS Servers: Multiple systems will
                                               nccoe@nist.gov; by telephone 301–975–                   section above). NIST published a notice               be configured as TLS servers (e.g.,
                                               0239; or by mail to National Institute of               in the Federal Register on October 19,                webserver, application server, or other
                                               Standards and Technology, NCCoE;                        2012 (77 FR 64314) inviting U.S.                      service). Certificates will be deployed
                                               9700 Great Seneca Highway, Rockville,                   companies to enter into a National                    and managed on these systems.
                                               MD 20850. Additional details about the                  Cybersecurity Excellence Partnerships                    • Load Balancer: A load balancer will
                                               TLS Server Certificate Management                       (NCEPs) in furtherance of the NCCoE.                  act as a TLS server with a certificate and
                                               Building Block are available at: https://               For this demonstration project, NCEP                  will facilitate the load balancing of
                                               nccoe.nist.gov/projects/building-blocks/                partners will not be given priority for               traffic to the other TLS servers.
                                               tls-server-certificate-management.                      participation.                                           • DevOps Framework(s): One or more
daltland on DSKBBV9HB2PROD with NOTICES




                                               SUPPLEMENTARY INFORMATION:                                 Building Block Objective: The                      DevOps frameworks (e.g., Docker) will
                                                  Background: The NCCoE, part of                       building block objective is to improve                be used to automate the management of
                                               NIST, is a public-private collaboration                 the overall security of TLS certificates              cloud instances and the deployment of
                                               for accelerating the widespread                         and private keys. A detailed description              certificates on those instances.
                                               adoption of integrated cybersecurity                    of the TLS Server Certificate                            • Internal CA: An internal CA will be
                                               tools and technologies. The NCCoE                       Management Building Block is available                used to issue certificates to some of the
                                               brings together experts from industry,                  at: https://nccoe.nist.gov/projects/                  TLS servers.


                                          VerDate Sep<11>2014   21:43 Dec 26, 2017   Jkt 244001   PO 00000   Frm 00009   Fmt 4703   Sfmt 4703   E:\FR\FM\27DEN1.SGM   27DEN1


                                               61260                    Federal Register / Vol. 82, No. 247 / Wednesday, December 27, 2017 / Notices

                                                  • Certificate Manager: A certificate                    NIST cannot guarantee that all the                 DEPARTMENT OF COMMERCE
                                               management system will be used to                       products proposed by respondents will
                                               inventory and manage TLS server                         be used in the demonstration. Each                    National Institute of Standards and
                                               certificates deployed in the                            prospective participant will be expected              Technology
                                               environment.                                            to work collaboratively with NIST staff
                                                  • Certificate Network Scanning Tool:                                                                       Notice of Localization and Tracking
                                                                                                       and other project participants under the              System Testing Consortium
                                               A tool, such as a vulnerability scanning                terms of the consortium CRADA in the
                                               or other tool, will be used to facilitate               development of the TLS Server                         AGENCY: National Institute of Standards
                                               the discovery of TLS server certificates                Certificate Management Building Block.                and Technology
                                               via network scanning.                                   Prospective participants’ contribution to             ACTION: Notice of Research Consortium
                                                  3. Stakeholders/Roles—Humans play                                                                          Deadline Extension.
                                               an important part in the management of                  the collaborative effort will include
                                               TLS server certificates in enterprises;                 assistance in establishing the necessary
                                                                                                                                                             SUMMARY:    On November 1, 2017, the
                                               therefore, the following roles will be                  interface functionality, connection and               National Institute of Standards and
                                               represented:                                            set-up capabilities and procedures,                   Technology (NIST) published a Federal
                                                  • Line of Business/Application                       demonstration harnesses, environmental                Register notice regarding the
                                               Owner: People in leadership positions                   and safety conditions for use, integrated             establishment of the Localization and
                                               who are responsible for the line of                     platform user instructions, and                       Tracking System (LTS) Testing
                                               business or application and who will                    demonstration plans and scripts                       Consortium, inviting organizations to
                                               drive the need for certificates to be                   necessary to demonstrate the desired                  participate in this Consortium. The
                                               deployed.                                               capabilities. Each participant will train             purpose of this Federal Register notice
                                                  • System Administrators:                             NIST personnel, as necessary, to operate              is to extend the deadline for acceptance
                                               Responsible for managing TLS servers                    its product in capability                             of letters of interest for participation in
                                               and ensuring that the load balancer will                demonstrations. Following successful                  the LTS Testing Consortium, as
                                               be represented.                                         demonstrations, NIST will publish a                   indicated in the DATES section below,
                                                  • DevOps Developer: Responsible for                  description of the security platform and              from December 15, 2017, to January 31,
                                               programming/configuring and managing                    its performance characteristics sufficient            2018.
                                               the DevOps framework.                                   to permit other organizations to develop              DATES: Letters of interest for
                                                  • Approver: One or more                                                                                    participation in this LTS Testing
                                                                                                       and deploy security platforms that meet
                                               stakeholders who will review and                                                                              Consortium will be accepted until
                                               approve/reject certificate management                   the security objectives of the TLS Server
                                                                                                       Certificate Management Building Block.                January 31, 2018. LTS testing is
                                               operations.                                                                                                   expected to occur in May or June 2018,
                                                  • PKI Team: One or more individuals                  These descriptions will be public
                                                                                                       information. Under the terms of the                   with a pre-event workshop in March.
                                               who will manage the certificate                                                                               Dates are subject to change, however.
                                               management system and public/internal                   consortium CRADA, NIST will support
                                                                                                       development of interfaces among                       ADDRESSES: Letters of interest and
                                               CAs.
                                                  Responding organizations need to                     participants’ products by providing IT                requests for additional information can
                                               understand and, in their letters of                     infrastructure, laboratory facilities,                be directed to the NIST LTS Testing
                                               interest, commit to provide:                            office facilities, collaboration facilities,          Consortium Manager, Nader Moayeri, of
                                                  1. Access for all participants’ project              and staff support to component                        the Advanced Network Technologies
                                               teams to component interfaces and the                                                                         Division of NIST’s Information
                                                                                                       composition, security platform
                                               organization’s experts necessary to make                                                                      Technology Laboratory. Nader
                                                                                                       documentation, and demonstration
                                               functional connections among security                                                                         Moayeri’s contact information is NIST,
                                                                                                       activities.                                           100 Bureau Drive, Stop 8920,
                                               platform components.
                                                  2. Support for development and                          The dates of the demonstration of the              Gaithersburg, MD 20899–8920, USA,
                                               demonstration of the TLS Server                         TLS Server Certificate Management                     email: nader.moayeri@nist.gov, and
                                               Certificate Management Building Block                   Building Block capability will be                     telephone: +1 301–975–3767.
                                               in NCCoE facilities which will be                       announced on the NCCoE website at                     FOR FURTHER INFORMATION CONTACT: For
                                               conducted in a manner consistent with                   least two weeks in advance at http://                 further information regarding the terms
                                               the following standards and guidance:                   nccoe.nist.gov/. The expected outcome                 and conditions of NIST’s CRADA,
                                               OMB Circular A–130; FIPS 200; FIPS                      of the demonstration is to improve                    please contact Jeffrey DiVietro, CRADA
                                               140–2; NIST Special Publications 800–                   security of TLS certificates and private              and License Officer, NIST’s Technology
                                               52, 800–57, 800–63–3, 800–77, 800–177;                  keys within the enterprise. Participating             Partnerships Office, by mail to 100
                                               NIST Framework for Improving Critical                   organizations will gain from the                      Bureau Drive, Mail Stop 2200,
                                               Infrastructure Cybersecurity; and                       knowledge that their products are                     Gaithersburg, Maryland 20899–2200, by
                                               internet Engineering Task Force (IETF)                  interoperable with other participants’                email to jeffrey.divietro@nist.gov, or by
                                               Requests for Comments (RFCs) 2246,                      offerings.                                            telephone at +1 301–975–8779.
                                               4346, 5280 and 5246. The project will                                                                         SUPPLEMENTARY INFORMATION:
                                                                                                          For additional information on the
                                               also be informed by two in-progress                                                                              On November 1, 2017, NIST
                                                                                                       NCCoE governance, business processes,                 published a Federal Register notice, 82
                                               IETF standards draft-ietf-tls-tls13–21
                                               The Transport Layer Security (TLS)                      and NCCoE operational structure, visit                FR 50626, regarding the establishment
                                               Protocol Version 1.3 and draft-ietf-acme-               the NCCoE website http://                             of the LTS Testing Consortium and
daltland on DSKBBV9HB2PROD with NOTICES




                                               acme-07 Automatic Certificate                           nccoe.nist.gov/.                                      inviting organizations to participate in
                                               Management Environment (ACME).                          Kevin Kimball,                                        this Consortium. The purpose of this
                                                  Additional details about the TLS                     NIST Chief of Staff.
                                                                                                                                                             new Federal Register notice is to extend
                                               Server Certificate Management Building                                                                        the deadline for acceptance of letters of
                                                                                                       [FR Doc. 2017–27893 Filed 12–26–17; 8:45 am]
                                               Block are available at: https://                                                                              interest for participation in the LTS
                                               nccoe.nist.gov/projects/building-blocks/                BILLING CODE 3510–13–P                                Testing Consortium from December 15,
                                               tls-server-certificate-management.                                                                            2017 to January 31, 2018. Participants in


                                          VerDate Sep<11>2014   21:43 Dec 26, 2017   Jkt 244001   PO 00000   Frm 00010   Fmt 4703   Sfmt 4703   E:\FR\FM\27DEN1.SGM   27DEN1



Document Created: 2017-12-27 02:23:36
Document Modified: 2017-12-27 02:23:36
CategoryRegulatory Information
CollectionFederal Register
sudoc ClassAE 2.7:
GS 4.107:
AE 2.106:
PublisherOffice of the Federal Register, National Archives and Records Administration
SectionNotices
ActionNotice.
DatesInterested parties must contact NIST to request a letter of interest template to be completed and submitted to NIST. Letters of interest will be accepted on a first come, first served basis. Collaborative activities will commence as soon as enough completed and
ContactTim Polk, William Haag, Jr. and Murugiah Souppaya via email to [email protected]; by telephone 301-975-0239; or by mail to National Institute of Standards and Technology, NCCoE; 9700 Great Seneca Highway, Rockville, MD 20850. Additional details about the TLS Server Certificate Management Building Block are available at: https://nccoe.nist.gov/projects/building- blocks/tls-server-certificate-management.
FR Citation82 FR 61258 

2025 Federal Register | Disclaimer | Privacy Policy
USC | CFR | eCFR